---
id: CVE-2026-97316
title: >-
  The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate
  the destination of redirects when checking links, allowing unauthenticated
  attackers to bypass its internal-address filter and make the server send
  requests to…
summary: >-
  The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate
  the destination of redirects when checking links, allowing unauthenticated
  attackers to bypass its internal-address filter and make the server send
  requests to…
severity: none
cwe:
  - CWE-918
product: Broken Link Notifier
affected:
  - broken_link_notifier >= 1.3.1 < 2.0.0.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:11.137'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97316'
references:
  - url: 'https://wpscan.com/vulnerability/d9497ddd-c39c-4928-8660-f1c94ef2c3a0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.560Z'
---

## Overview

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
